Windows is pretty much the only OS left that doesn't support encryption by default.
Windows is pretty much the only OS left that doesn't support encryption by default.
From an end-user perspective it seems to behave very transparent as well. In what way does it come up short?
[1] https://technet.microsoft.com/en-us/library/hh831627(v=ws.11...
[2]https://helgeklein.com/blog/2015/01/how-to-enable-bitlocker-...
By forcing an escrow key linked to Microsoft and whomever owns the TPM on your computer.
By definition, backdoor keys and hidden users who can access encrypted content is just absolutely, horribly wrong. And there's no way to turn it off... Well, I'm sure someone will say there's 10 regkeys to change that might fix it on a specific version.
Still does nothing regarding the "trust" with the TPM.
That's why the whole excercise is meaningless if you leave the keys on the device, and why you should put them on external hardware TPMs or key vaults. Even a YubiKey is better.
Now you just need a system that supports reading keys from such a device during boot.
The TPM is a PKI device, nothing more. It cannot take over your computer.
Their encryption by definition, is already backdoored to MS. Game over.
And that's nothing about the stupidity of the TPM itself.
This statement is misleading. When setting up bitlocker, you have the option of saving your recovery key to onedrive. It's not mandatory or even the default choice.